
[CIVN-2025-0358] Multiple Vulnerabilities in Zoom
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Zoom
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Zoom Rooms for Windows before version 6.6.0
Zoom Rooms for macOS before version 6.6.0
Overview
Multiple vulnerabilities have been reported in Zoom products that could be exploited by an attacker to elevate privileges and disclose sensitive information on the targeted system.
Target Audience:
All end-user organisations and individuals using Zoom applications.
Risk Assessment:
High risk of data manipulation and unauthorized access to sensitive information.
Impact Assessment:
Potential compromise of application integrity and service disruption.
Description
Multiple vulnerabilities exist in Zoom products due to external control of file name or path and Protection Mechanism Failure of software-downgrade in the affected applications.
Successful exploitation of these vulnerabilities could allow an attacker to elevate privileges and disclose sensitive information on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor given below:
https://www.zoom.com/en/trust/security-bulletin/zsb-25051
https://www.zoom.com/en/trust/security-bulletin/zsb-25050
Vendor Information
Zoom
https://www.zoom.com/en/trust/security-bulletin/
References
https://www.zoom.com/en/trust/security-bulletin/zsb-25051
https://www.zoom.com/en/trust/security-bulletin/zsb-25050
CVE Name
CVE-2025-67460
CVE-2025-67461
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmk8H+oACgkQ3jCgcSdc
ys927xAAhhbJzv96JKLLt2bhbj/Ps65ZgzEjNxHBBS3BLFRT84GNfnyjcIn+22H8
9wndYSJjI2tiZtqUMqFk2giYpt0fXFZXyTyv3+WFPl7BfMVg4t6UjxRBjuHlv0OB
cb6txM9XvHwxBAoCJG1doTLPDwUNTFgaINULvEADzfYKDUgCqyK7YWuhlqF9Pbl5
bVgENJN464CRrKF6i7pHjbGpf3pt/cP30iYaT1csvKqDYVATjtBrNxq/TZPJ8MqY
ztLzrbMIos6ortUm7tnqykWgpu4y2x9Ry5wsqRtgGJQnk7m57XHwFGkI7BPRTl5G
RiGxA5eZ51IQnDg2/1uZBbRk/3uCASpcvRTgP3CGwuZ5ow9ka8mOm7upL/ls9A7m
sli4/cK16NhCpZgPW5BgNh2F3GyCLfJ8Di+kwtlB26PJ2SbvmiBBC+IfGs+PlEUg
8L9BjmKw+xhjGfndbYRlA8aHHajyriFErDbETalaLKt/Pl9EWexM5ToO6tYarOjT
JTBzXkfDk9UHphpRKkXOb85BHRJc4RDTURxRwg9hG6C4STEAwnfrdC+kLRlB8OYk
3llxJ7aNO/h90Npb3lsn+AaX7E3+SYJQPe+6K5rzK7Sfo30xtjr3GrCBDv0oH2VL
2Y5faB4a6tQxdysFfoS0IQGbEydONpqGtY9xFX7XOVh3uIEvZhU=
=I2xX
—–END PGP SIGNATURE—–


